Information Security Risk and Compliance Analyst
Job Description
<div class="content-intro"><p><strong>Who we are</strong></p> <p>At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years.</p> <p><strong>What we do</strong></p> <p>The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. But they're not the only ones who love CarGurus—our employees do, too. We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride!</p></div><p><strong>Role overview</strong></p> <p>The information security risk and compliance analyst supports the organization’s governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and partnering across the business to strengthen the company’s security posture. This role is responsible for third party risk management, customer security assurance activities, cyber risk management, SOX IT General Controls and security governance initiatives. The analyst works closely with security, engineering, legal, internal audit, privacy, finance, procurement and business stakeholders to build scalable processes, improve operational maturity and reduce organizational risk. </p> <p><strong>What you'll do</strong></p> <ul> <li>Third Party Risk Management</li> <li>Customer Security Assurance</li> <li>Cyber Risk Management</li> <li>SOX Compliance</li> <li>Governance and Compliance</li> </ul> <p><strong>What you'll bring</strong></p> <ul> <li>Experience with GRC platforms such as Auditboard, SAFE, Loopio or similar tools.</li> <li>Professional certifications such as CISSP, CISA, CRISC, Security+ or CISM.</li> <li>Experience supporting cloud environments.</li> <li>Familiarity with AI governance, automation or security workflow optimization.</li> </ul> <p><strong>Successful candidates will</strong></p> <ul> <li>Build trusted partnerships with technical and business teams.</li> <li>Drive scalable governance and risk management processes.</li> <li>Balance business enablement with effective risk management.</li> <li>Improve audit readiness and compliance maturity.</li> <li>Communicate complex security concepts clearly to both technical and non-technical stakeholders.</li> <li>Continuously identify opportunities to improve security governance through process optimization and automation. </li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p><span data-sheets-root="1">The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles.<br><br>Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and rel